CrowdStrike Wants AI Agents Rechecked Before Every Action
The company’s approach makes an agent’s authority temporary: access is scoped to a job and can be withdrawn when that job ends or risk conditions change.
Listen to this story
The audio brief
Story brief
3 key pointsCrowdStrike is positioning Continuous Identity for AI Agents as an authorization layer that can change throughout an agent’s work, not just at login. The capability, built after its $740 million SGNL acquisition and productized in June, evaluates human and agent permissions alongside device and security context, then can revoke access mid-task. CrowdStrike says Falcon AI Detection and Response also monitors prompts...
- 01
CrowdStrike announced its $740 million SGNL acquisition in January and productized the capability as Continuous Identity for AI Agents in June.
- 02
Authorization considers the agent owner, caller, device risk, entitlements, and current business context before each action.
- 03
CrowdStrike says delegated sub-agents retain the initiating human’s identity and permissions; read-only users cannot authorize writes.
An AI agent’s access can now be treated as a series of decisions rather than a privilege that lasts for a full login session. CrowdStrike highlighted that model, called Continuous Identity for AI Agents, during its Fal.Con 2026 keynote program in Las Vegas.
Access that expires with the job
CrowdStrike’s system continuously authorizes agent actions instead of trusting an agent for an entire session. It grants short-lived authorization for specific tasks and can revoke access when a task ends. Before approving an action, it evaluates the agent’s owner, the caller and the device’s risk posture.
A decision can be reversed
The design’s key operational feature is revocation after an initial approval. CrowdStrike says it can immediately remove access when the context changes, including when a vulnerability is discovered or an employee’s HR status changes. The company says the capability uses SPIFFE, an identity standard, and the Shared Signals Framework for real-time authorization.
The company’s stated control model
- Every action is assessed against both the agent’s and the human’s entitlements, plus current security and business context.
- A read/write agent acting for a read-only user can only read, CrowdStrike says.
- When an agent delegates to a sub-agent, the company says the human identity and permissions are preserved.
A second check on agent behavior
CrowdStrike says the capability is delivered through Falcon Next-Gen Identity Security and Falcon AI Detection and Response. The latter continuously inspects prompts and intent for permission misuse or attempts to manipulate a language model beyond its authorized scope, and can trigger revocation before damage is done.
The company’s case for speed
CrowdStrike researcher Adam Meyers said AI agents are generating roughly 250 times more detections than humans. Separately, CrowdStrike threat research cited in the article found that average eCrime breakout time had fallen to 29 minutes, with the fastest recorded intrusion at 27 seconds. Those company figures frame the push for access controls that can change while an agent is working.
Sources
- siliconangle.comContinuous AI agent identity becomes a 24/7 job at Fal.Con - SiliconANGLE
- crowdstrike.comwww.crowdstrike.com